Account security has a reputation for complexity that the reality does not deserve. The layered defense that stops most takeovers — password manager, multi-factor authentication, passkeys, recovery planning — fits in an afternoon of setup. Do the steps in order; each builds on the last.

Step 1: Password manager (30 minutes)

Install a reputable password manager, let it generate unique random passwords, and change your most important accounts first: email, banking, primary work. Reused passwords are how one breach becomes ten; uniqueness is the whole game. You will remember exactly one strong master password — write that on paper and store it somewhere genuinely safe.

Step 2: Multi-factor authentication (30 minutes)

Enable MFA everywhere it exists, in this order of strength: passkeys and hardware keys, authenticator apps, then SMS. Prioritize email and financial accounts. SMS codes still beat nothing, but app-based codes resist SIM-swap attacks that have drained real people's accounts.

Step 3: Passkeys (15 minutes per account)

Where a service offers passkeys — major email, social, and financial platforms increasingly do — enable them and delete the password. Start with email again: it is the recovery hub for everything else, so phishing-proofing it protects the whole chain.

Step 4: Recovery and hygiene (1 hour)

  • Check each critical account's recovery email, phone, and backup codes — stale phone numbers strand people out of their lives.
  • Store backup codes on paper, not in the same password manager.
  • Review connected apps and active sessions; revoke what you do not recognize.
  • Set a calendar reminder to review this annually.

What this buys you

This is not invulnerability — it is proportionality. With unique passwords, strong MFA, and clean recovery paths, the realistic attacks against you (phishing, credential stuffing, SIM swaps) all fail structurally. That afternoon of setup moves your accounts from "easy target" to "harder than the next person," which in security is most of the victory.

Passkey enrollment: the detailed walkthrough

The passkey enrollment from Step 3 deserves its own walkthrough because the details vary by platform and the mistakes lock people out. On the service: navigate to the security settings, find the passkey option, and follow the prompt — your device will ask for biometric or PIN confirmation. What gets stored: the private key on your device (or synced through your platform's keychain — iCloud Keychain, Google Password Manager), with the public key registered to the service. The device question: a passkey created on your phone stays on your phone (unless synced); one created through a synced keychain becomes available on all devices logged into that platform account. Testing: sign out and sign back in with the passkey to confirm it works before deleting the password. Multi-device strategy: register passkeys on two devices (phone and computer) where the service allows, so losing one does not strand you. The passkey walkthrough from our passkeys guide covers the security model; this walkthrough covers the clicking.

Password managers: choosing and using one well

The password manager is the foundation of the entire security stack, and the choice matters less than the commitment to using it. The reputable options: the platform built-ins (Apple Keychain, Google Password Manager) for simplicity, and the dedicated managers (Bitwarden, 1Password) for cross-platform flexibility and advanced features. The evaluation criteria: cross-platform availability (phone, computer, browser), security track record (has it been independently audited and how did it respond to findings), encryption model (zero-knowledge — the provider cannot read your vault), and the emergency-access feature (a trusted person can access your vault if you are incapacitated). The usage habits that make it work: the manager is the only place passwords live (no browser-saved passwords, no sticky notes), the master password is strong and memorized (not written in a drawer), and the emergency kit (recovery code, master password hint) is stored physically — not in the same digital system it unlocks.

What to do about the breaches you cannot prevent

The layered defense from this guide prevents most account takeovers, but some breaches happen at the service level — the company's database leaks, not your credential reuse. The response protocol for service-level breaches (from our 48-hour guide): rotate the exposed password (the manager makes this thirty seconds per account), check for MFA bypass, watch financial statements if payment data was exposed, and monitor the email account the service used — the follow-up phishing is where the real damage happens. The service's notification tells you what was exposed; your response depends on the data type. The password manager's breach-monitoring feature (most have one) alerts you automatically when your email appears in known breaches — the proactive watch that turns the notification from a surprise into a routine rotation.

Family and shared-device security

Account security in a household with shared devices and family members has its own considerations. Shared devices: separate user profiles on shared computers and tablets, each with their own browser profiles (which keep passwords and sessions separate), and the household rule that sensitive accounts (banking, email) are accessed only from personal profiles. Children's accounts: platform-supervised accounts (Google Family Link, Apple Family) with the parent's oversight, age-appropriate security (the child's first password manager account with the parent as recovery), and the education that makes security a habit rather than a rule. Elderly family members: the most targeted population for phone scams and phishing — the practical help: setting up their password manager, enabling their MFA, and being the listed emergency contact for their accounts. Household recovery: the agreed protocol for what happens when someone is locked out, loses their device, or the household's shared accounts need password rotation — a document, not a memory. The family that has the security conversation once a year is the family that avoids the group-chat panic when something goes wrong.

The monitoring layer: knowing when something is wrong

The security stack from this guide prevents most attacks, but the monitoring layer tells you when prevention fails. The tools: breach-notification services (the password manager's built-in monitoring, or a dedicated service like Have I Been Pwned) that alert you when your email appears in known breaches. The habits: monthly financial statement review (the fraudulent charge caught in thirty days costs less than one caught in ninety), annual credit report review (free by law in most jurisdictions), and the device-security check — are the updates running, is the antivirus active, are there unknown devices on the network. The response to an alert from the monitoring layer is the same 48-hour playbook from our breach-response guide — the monitoring makes the response proactive rather than reactive, which is the difference between a routine rotation and a crisis.

Business accounts: the additional layer

Business accounts carry security obligations beyond personal ones, because the blast radius of a compromise includes customers, employees, and partners. The business-account security checklist: SSO (single sign-on): one strong credential (with MFA) protecting all business applications — the enterprise standard that eliminates password reuse across work tools. Least-privilege access: each employee's accounts access only what their role requires — the principle that limits the blast radius of any single compromise. Offboarding protocol: the documented procedure for revoking all access when an employee leaves — the forgotten contractor account is a classic breach vector. Business password manager: a team vault separate from personal passwords, with shared credentials for team resources and individual vaults for personal ones. Security review: an annual audit of who has access to what, which accounts have MFA, and whether the recovery methods are current. The business security layer builds on the personal one from this guide — the same principles (unique passwords, MFA, monitoring) applied at organizational scale, with the blast radius as the multiplier that makes the discipline non-negotiable.